Blog
TeamPCP Poisoned Trivy, KICS, and LiteLLM to Harvest 500,000 Credentials — Now Vect Ransomware Is Cashing In
TeamPCP compromised Trivy, KICS, and LiteLLM to steal 500,000 CI/CD credentials across 500,000 machines. Now Vect ransomware is deploying against victims — and paying the ransom may not recover your…
Read More →JadePuffer: The World’s First Fully Autonomous AI Ransomware Has Arrived — And It Needs No Human Operator
JADEPUFFER is the first confirmed ransomware campaign executed entirely by a large language model agent — exploiting CVE-2025-3248 (CVSS 9.8) in Langflow to autonomously encrypt 1,342 production configs without any…
Read More →Iran’s CyberAv3ngers Are Inside Your Water and Energy Systems — CISA’s July 22 Update Expands Alert to Siemens and Schneider PLCs
CISA updated AA26-097A on July 22, 2026: Iran-backed CyberAv3ngers now target Siemens & Schneider PLCs. CVE-2021-22681 has no patch — act now.
Read More →China-Linked UAT-7810 Turns Ruckus and ASUS Routers Into Covert Spy Relays — The LapDogs ORB Network Is Growing
China-nexus APT UAT-7810 hijacks unpatched Ruckus and ASUS routers with LONGLEASH malware to build a covert ORB relay network — CVE-2023-25717 (CVSS 9.8) and CVE-2025-2492 (CVSS 9.2) are the entry…
Read More →CVE-2026-50522 (CVSS 9.8): SharePoint Machine Key Theft Turns Patched Servers Into Persistent Backdoors
CVE-2026-50522 (CVSS 9.8) pre-auth SharePoint RCE is actively exploited to steal IIS machine keys — granting persistent backdoor access that survives patching. Here is the technical breakdown and what to…
Read More →CVE-2026-6875 (CVSS 9.5): No Password Required — Attackers Are Actively Exploiting ServiceNow’s Pre-Auth Sandbox Escape
CVE-2026-6875 (CVSS 9.5) lets unauthenticated attackers escape ServiceNow’s sandbox and execute code remotely. Active exploitation confirmed since July 18, 2026. Self-hosted customers must patch immediately.
Read More →Hugging Face Hacked by Autonomous AI Agent: 17,000 Actions, Stolen Credentials — AI-on-AI Attacks Are Here
Autonomous AI agent hacked Hugging Face, executing 17,000 actions to steal credentials and move laterally across clusters. Here's what happened and how to defend your AI infrastructure.
Read More →CVE-2026-42533: NGINX’s Hidden 15-Year Flaw (CVSS 9.2) Threatens Every Web Server — Patch Before the PoC Drops
CVE-2026-42533 is a critical NGINX heap buffer overflow (CVSS 9.2) hiding since 2011. Patch to nginx 1.30.4 or 1.31.3 now — a PoC exploit drops by 5 August.
Read More →GodDamn Ransomware’s Signed PoisonX Driver Is Silently Killing Your EDR — Inside Hyadina’s BYOVD Playbook
Hyadina's GodDamn ransomware uses a Microsoft-signed malicious kernel driver (PoisonX/g11.sys) to disable EDR and AV before encrypting 10+ hosts. Here's the full BYOVD attack chain and how to stop it.
Read More →FEDERAL DEADLINE TODAY: CVE-2026-58644 SharePoint Zero-Day (CVSS 9.8) Exploited in the Wild — CISA Mandates Immediate Patching
CVE-2026-58644 (CVSS 9.8) is a zero-day unauthenticated RCE in SharePoint Server now on CISA's KEV list. Federal deadline is today — here's what to patch and how to check if…
Read More →